Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Cybersecurity › Guide to Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC) Implementation
| Type | Guideline |
|---|---|
| Issuing authority | National Cybersecurity Authority (NCA) |
| Framework | Cybersecurity |
| Tier | Guidelines & circulars |
| Legal status | Guidance |
The Guide to Organizations' Social Media Accounts Cybersecurity Controls Implementation (GOSMACC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Organizations' Social Media Accounts Cybersecurity Controls (OSMACC-1:2021), which set the minimum requirements for organisations' safe official use of social networks.
The guide presents the OSMACC domains and subdomains: cybersecurity governance (policies and procedures, risk management, human resources, and awareness and training), cybersecurity defence (asset management, identity and access management, protection of information systems and processing facilities, mobile-device security, data and information protection, event-log monitoring, and incident and threat management) and third-party cybersecurity, then provides a general implementation guideline followed by guidance under each domain. It supports the OSMACC's ECC-aligned compliance model, in which continuous compliance with the Essential Cybersecurity Controls is a prerequisite.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13